220-1101 Networking Practice Question
A user reports that they can access internal company servers by IP address and hostname, but cannot browse the internet. The user can ping the default gateway (192.168.1.1) successfully. Other users on the same subnet have full internet access. The technician checks the user's IP configuration and sees that the IP address, subnet mask, default gateway, and DNS server (192.168.1.10) are all correct. Which of the following should the technician check NEXT?
⚠ Common exam trap
CompTIA often tests the concept that successful ping to the default gateway and correct IP configuration do not guarantee internet access, and candidates mistakenly focus on DHCP or gateway issues instead of application-layer settings like proxy configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the browser's proxy settings
Since the user can access internal resources by hostname (indicating DNS resolution works for internal names) and can ping the default gateway, the issue is isolated to internet-bound traffic. The most likely cause is that the browser is configured to use a proxy server that is unreachable or misconfigured, which would prevent internet access while leaving local network connectivity intact. Checking the browser's proxy settings is the logical next step because the user's IP configuration is correct and other users on the same subnet have full internet access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Check the browser's proxy settings
Why this is correct
A proxy configured in the browser intercepts HTTP/HTTPS requests and forwards them through the specified server. If that proxy is an internal server with no outbound internet route—or is simply unreachable—requests to external domains fail, yet direct access to internal IP addresses (which bypasses the proxy) remains functional. Since the issue is isolated to the user's browsing and internal IP access works, inspecting the browser's proxy settings (including any PAC file or system-level proxy) is the correct next step.
- ✗
Check the default gateway
Why it's wrong here
The default gateway is the router interface that forwards packets to destinations outside the local network. The user successfully pings the gateway, proving Layer 3 connectivity to that router; if the gateway were wrong, the ping would fail or the interface would be unreachable. Furthermore, an incorrect or down gateway would prevent access to both external and remote internal networks, not specifically internet websites, while direct internal server access would still work only if on the same subnet. Therefore re-checking the gateway is redundant.
When this WOULD be correct
A user cannot access any network resources (internal or external) and cannot ping the default gateway. The technician would then check the default gateway configuration or its status.
- ✗
Check the DHCP lease status
Why it's wrong here
The DHCP lease determines the client's IPv4 address, mask, gateway, and DNS servers. If the lease were expired, conflicted, or misassigned, the user would typically see an APIPA address (169.254.x.x) or an incorrect gateway, causing total loss of connectivity beyond the local subnet. Because the user has a valid IP configuration, can ping the gateway, and reaches internal servers by IP, the lease is not the culprit; a DHCP fault would also likely affect other clients on the same broadcast domain.
When this WOULD be correct
A user cannot access network resources and has an IP address starting with 169.254.x.x (APIPA) or an incorrect IP. The technician should check the DHCP lease status to see if the client received a valid lease.
- ✗
Check the switch port security settings
Why it's wrong here
Switch port security works by restricting the number of MAC addresses or locking a port to a specific MAC; a violation triggers an error-disabled state or frame filtering that halts all traffic on that port. Since the user's client can still communicate with internal servers and the gateway, the port is forwarding normal traffic, so the switch has not blocked the client. Port security operates at Layer 2 and cannot selectively block outbound internet HTTP/HTTPS while permitting internal IP traffic, so it is not a plausible cause.
When this WOULD be correct
A technician would check switch port security when a user cannot access any network resources (neither internal nor external) while other users on the same switch can, and the port shows err-disable or security violations.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 220-1101 exam frequently reuses these exact scenarios with slightly different constraints.
✓Check the browser's proxy settingsCorrect answer▾
Why this is correct
A proxy configured in the browser intercepts HTTP/HTTPS requests and forwards them through the specified server. If that proxy is an internal server with no outbound internet route—or is simply unreachable—requests to external domains fail, yet direct access to internal IP addresses (which bypasses the proxy) remains functional. Since the issue is isolated to the user's browsing and internal IP access works, inspecting the browser's proxy settings (including any PAC file or system-level proxy) is the correct next step.
✗Check the default gatewayWrong answer — click to see why▾
Why this is wrong here
The user can ping the default gateway successfully, indicating the gateway is reachable and functioning. The issue is internet access, not local connectivity, so checking the gateway again is unnecessary.
★ When this WOULD be the correct answer
A user cannot access any network resources (internal or external) and cannot ping the default gateway. The technician would then check the default gateway configuration or its status.
Why candidates choose this
Candidates may assume internet issues are always gateway-related, overlooking that successful ping to the gateway rules out that problem.
✗Check the DHCP lease statusWrong answer — click to see why▾
Why this is wrong here
The user's IP configuration is correct, and other users on the same subnet have internet access, so DHCP is functioning properly. The issue is isolated to this user, not a DHCP lease problem.
★ When this WOULD be the correct answer
A user cannot access network resources and has an IP address starting with 169.254.x.x (APIPA) or an incorrect IP. The technician should check the DHCP lease status to see if the client received a valid lease.
Why candidates choose this
Candidates may think internet access failure is due to DHCP issues, but the user has a correct IP and gateway, ruling out DHCP problems.
✗Check the switch port security settingsWrong answer — click to see why▾
Why this is wrong here
The user can access internal servers by hostname, indicating DNS resolution works. The issue is internet access only, and other users on the same subnet have full access, so switch port security is not the cause.
★ When this WOULD be the correct answer
A technician would check switch port security when a user cannot access any network resources (neither internal nor external) while other users on the same switch can, and the port shows err-disable or security violations.
Why candidates choose this
Candidates may think port security could block internet traffic, but it typically blocks all traffic based on MAC address, not selectively internet-only.
Analysis generated from the official 220-1101blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Quick reference
IPv4 Address Class Summary
| Class | First Octet Range | Default Mask | Networks | Hosts per Network |
|---|---|---|---|---|
| A | 1–126 | /8 (255.0.0.0) | 126 | 16,777,214 |
| B | 128–191 | /16 (255.255.0.0) | 16,384 | 65,534 |
| C | 192–223 | /24 (255.255.255.0) | 2,097,152 | 254 |
| D | 224–239 | N/A | Multicast groups | — |
| E | 240–255 | N/A | Reserved / experimental | — |
127.x.x.x is reserved for loopback. Modern networks use CIDR (classless) rather than classful addressing.
Go deeper
Related to this question
About these practice questions
One of 896 original 220-1101 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.